Skip to content
ThreatCluster

WebRAT Malware Campaign Exploits GitHub for Distribution

First seen 24 Dec 2025, 12:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Kaspersky has identified 15 malicious GitHub repositories spreading WebRAT malware disguised as proof-of-concept exploits. Some of these exploits are reportedly crafted with generative AI technology, and victims receive ZIP files containing decoy files. This campaign targets users seeking legitimate software and poses risks to their systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 198d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track WebRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed